A method and system for remote setting of a relay protection device
By using encrypted communication and a verification mechanism of the local authorized management unit, the problems of low efficiency and safety hazards in remote operation of relay protection device settings are solved, and more reliable and secure setting management is achieved.
Patent Information
- Application Number
- CN202311248682.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-26
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2043-09-26
AI Technical Summary
In existing technologies, remote operation of relay protection device settings is inefficient and poses safety risks, especially in smart substations and unattended scenarios, where the security and reliability of communication networks are difficult to guarantee.
The system uses encrypted communication to send out unique identification codes, authorization information, and signatures, which are verified by the authorization management unit of the local operation station to ensure the legitimate operation of the relay protection device, record authorization logs, prevent unauthorized intrusion, and improve system reliability and security.
While reducing system complexity, it improves the reliability and security of remote operation of relay protection device settings, prevents unauthorized modifications, and enhances the overall efficiency of the system.
Smart Images

Figure CN119727092B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the remote management technology of the setting value of the relay protection device in the transformer substation, and in particular to a relay protection device setting value remote operation method based on the authorization verification of the local operation station. BACKGROUND
[0002] The relay protection device is the first barrier for the safe and reliable operation of the power grid, and the setting value is the basis for the correct action of the relay protection device. The correctness and adaptability of the setting value play a very important role in the correct action of the relay protection device and the safe operation of the power grid. At present, the setting value setting mode of the relay protection device mainly includes two kinds, one is the manual modification and checking, and the other is the mode of step-by-step forwarding modification based on the informationization point table mapping. The former has a large amount of manual operation and low efficiency, and the latter has multiple communication mapping conversion links, which increases the complexity of the system.
[0003] With the popularization of intelligent transformer substations and unattended operation, the relay protection device setting value remote operation method based on the file mode is proposed, and the communication link is simplified to the file transmission and instruction response between the master station and the relay protection device. However, the simplification of the setting value remote management also has security risks. The communication network inside the transformer substation and the communication network information security between the transformer substation and the dispatching end will affect the reliability of the relay protection device setting value remote operation. SUMMARY
[0004] The purpose of the present application is to provide a relay protection device setting value remote operation method and system, which can reduce the complexity of the system while improving the reliability of the relay protection device setting value remote operation.
[0005] In order to achieve the above purpose, the solution of the present application is:
[0006] A relay protection device setting value remote operation method, comprising the following steps:
[0007] Step A, the master station sends the unique identification code of the relay protection device, the authorization information and the signature to the local operation station through the encrypted communication mode;
[0008] Step B, the local operation station enters the authorization management unit corresponding to the relay protection device based on the unique identification code, checks the validity of the authorization information and the signature based on the authorization information and the signature, and opens the authorization function if the check is passed;
[0009] Step C, the master station initiates the viewing or modification of the setting value instruction to the relay protection device, and sends the signature at the same time;
[0010] Step D, the relay protection device sends the received signature together with its own unique identification code to the local operation station to apply for authorization;
[0011] Step E, the local operation station enters the authorization management unit corresponding to the relay protection device based on the unique identification code, and performs signature verification. If the verification is passed, the authorization command is fed back to the relay protection device, otherwise the authorization is not granted;
[0012] Step F, the relay protection device generates or executes the setting value file according to the authorization command in response to the setting value instruction from the master station.
[0013] The signature issued by the master station is formed based on the authorization information.
[0014] The local operation station authorization management system instantiates a separate authorization management unit for each relay protection device in the substation.
[0015] The local operation station records authorization log information, including each time the authorization information is checked.
[0016] There is at most one valid authorization information in each authorization management unit. When the latest authorization information is received, the historical authorization information is invalid. Each authorization information is used for authorization verification at most once, and is invalid immediately after verification. After the authorization information is invalid, the authorization management unit no longer responds to the authorization application of the corresponding relay protection device before the authorization information is updated.
[0017] In step F, the relay protection device generates an original setting value file in response to the setting value instruction from the master station for the master station to view; or the relay protection device parses the updated setting value file from the master station in response to the setting value instruction from the master station to modify the setting value of the device.
[0018] Before initiating the setting value instruction, the master station re-forms the authorization information and issues it to the local operation station to activate the authorization management unit.
[0019] A relay protection device setting value remote operation system for implementing the relay protection device setting value remote operation method as described above; comprising a master station, a local operation station and a plurality of relay protection devices;
[0020] The master station is configured to issue the unique identification code of the relay protection device, the authorization information and the signature to the local operation station through an encrypted communication mode;
[0021] The local operation station is configured to enter the authorization management unit corresponding to the relay protection device based on the unique identification code, and to check the validity of the authorization information and the signature based on the authorization information and the signature. If the verification is passed, the authorization function is opened;
[0022] The master station is also configured to initiate a setting value instruction to the relay protection device after the authorization function is opened, and to send the signature at the same time.
[0023] The relay protection device is further configured to send the received signature and a self-unique identification code to a local operation station to apply for authorization;
[0024] The local operation station is further configured to enter an authorization management unit corresponding to the relay protection device based on the unique identification code, to perform signature verification, and to feed back an authorization command to the relay protection device if the signature verification is passed, or not to authorize if the signature verification fails.
[0025] The relay protection device is further configured to generate or execute a setting value file according to the authorization command in response to the main station checking or modifying a setting value instruction.
[0026] After the above scheme is adopted, the application can avoid the single-line communication between the main station and the relay protection device from being affected by illegal intrusion, thereby avoiding the problem of illegal modification of the setting value of the protection device, improving the efficiency of remote management of the setting value of the device, and improving the reliability and security of the system. BRIEF DESCRIPTION OF DRAWINGS
[0027] Figure 1 is a schematic diagram of an embodiment of the application;
[0028] Figure 2 is a schematic diagram of an embodiment of the application in which the main station checks the setting value N of a certain relay protection device;
[0029] Figure 3 is a schematic diagram of an embodiment of the application in which the main station modifies the setting value N of a certain relay protection device. DETAILED DESCRIPTION
[0030] The technical solutions and beneficial effects of the application will be described in detail below with reference to the accompanying drawings.
[0031] The application provides a relay protection device setting value remote operation system, which comprises a main station, a local operation station and a relay protection device, and the functions and responsibilities among the three can be simplified as the main station remotely operating the setting value of the relay protection device based on a file-based mode; before responding to the operation instruction of the main station, the relay protection device needs to apply for authorization to the local operation station; the local operation station manages the authorization of the relay protection device to respond to the instruction of the main station for remotely operating the setting value, and the authorization is based on the information from the main station, and the authorization log information is recorded.
[0032] The main station is a general term of a remote dispatching function system, which comprises a setting value management system, an encryption management system, a communication service management system and the like, and the main station is the initiator of the setting value checking and modification, and needs to have a signature encryption distribution function in addition to the setting value management function. The local operation station instantiates a separate authorization management unit based on each relay protection device in the station, checks and authorizes the relay protection device to respond to the request instruction of the main station, and records the check and authorization information. The relay protection device is a terminal responder, and can only generate or execute a setting value file under the authorization of the local operation station.
[0033] The relay protection device in the transformer substation establishes a unique identification code, which can be used as a communication identifier between the local operation station, the master station and the relay protection device. The local operation station and the master station adopt an encrypted communication mode to obtain the authorization information and signature issued by the master station, which is used as the judgment basis for authorization management. In the authorization management unit, there is at most one valid authorization information, and the latest one is received, and the historical authorization information is invalid; each authorization information is used for authorization verification at most once, and is invalid immediately after verification. After the authorization information is invalid, the authorization management unit does not respond to the authorization application of the corresponding relay protection device before the authorization information is updated.
[0034] The local operation station authorization management system instantiates a separate authorization management unit based on each relay protection device in the transformer substation, and manages the authorization and permission of the relay protection device responding to the master station to view or modify the setting value instruction. At the same time, the local operation station has the function of recording and saving the relevant information of each authorization verification, which is convenient for tracing the log record of the remote management of the setting value of each relay protection device in the transformer substation.
[0035] The relay protection device and the master station follow the same setting value model specification, and both have the ability to independently interpret the setting value file. After obtaining the authorization permission of the local operation station, the relay protection device can respond to the master station to view the setting value instruction, generate the original setting value file, and provide the master station for viewing; and can respond to the master station to modify the setting value instruction, analyze and verify the updated setting value file from the master station, and modify the device setting value.
[0036] Before initiating the instruction of viewing or modifying the setting value of the relay protection device, the master station needs to re-form the authorization information and issue it to the local operation station to activate the authorization management unit.
[0037] The application also provides a relay protection device setting value remote operation method, which is based on the foregoing system and realizes the management of the master station to the setting value of the relay protection device.
[0038] The steps of the master station viewing the setting value of the relay protection device are as follows:
[0039] 1) The master station forms the authorization information according to a certain rule, forms the information digest based on the authorization information and signs.
[0040] 2) The master station sends the unique identification code of the relay protection device, the authorization information and the signature to the local operation station through an encrypted channel.
[0041] 3) The local operation station enters the corresponding authorization management unit according to the unique identification code, and checks the validity of the information based on the authorization information and the signature. If the verification is inconsistent, the authorization information and the verification failure log are recorded, and the authorization function is maintained in a closed state; if the verification is passed, the authorization information of the unit is updated, the authorization function is opened, and the authorization application of the relay protection device is waited.
[0042] 4) The master station sends the signature to the relay protection device and initiates the request for viewing the setting value.
[0043] 5) The relay protection device sends the signature to the local operation station based on the unique identification code information, and requests the authorization responding to the viewing setting value command of the master station;
[0044] 6) The local operation station enters the authorization management unit of the corresponding relay protection device based on the unique identification code, and if the authorization function is closed, the authorization is denied this time, and the authorization denial log is recorded. If the authorization function is open, the signature can be verified, if the verification fails, the authorization is denied this time, and the authorization information and authorization failure log are recorded, and the authorization function is closed; if the verification is successful, the device authorizes the master station to respond to the command, records the authorization information and authorization success log, and closes the authorization function.
[0045] 7) The relay protection device receives the authorization command of the local operation station, and generates the original setting value file;
[0046] 8) The relay protection device notifies the master station that the setting value file is successfully generated;
[0047] 9) The master station calls the setting value file through the file service, and verifies the setting value file according to the model specification.
[0048] The steps for the master station to modify the setting value of the relay protection device are:
[0049] 1) The master station modifies the setting value based on the called original setting value file, forms an updated setting value file, and sends the updated setting value file to the relay protection device through the file service;
[0050] 2) The master station forms the authorization information according to certain rules, forms the information digest based on the authorization information and signs.
[0051] 3) The master station sends the unique identification code of the relay protection device, the authorization information and the signature to the local operation station through the encrypted channel.
[0052] 4) The local operation station enters the corresponding authorization management unit according to the unique identification code, and checks the validity of the authorization information and the signature. If the verification is inconsistent, the authorization information and the verification failure log are recorded, and the authorization function is maintained in the closed state; if the verification is passed, the authorization information of the unit is updated, the authorization function is opened, and the authorization application of the relay protection device is waited.
[0053] 5) The master station sends the signature to the relay protection device and initiates the request for modifying the setting value.
[0054] 6) The relay protection device sends the signature to the local operation station based on the unique identification code information, and requests the authorization responding to the viewing setting value command of the master station;
[0055] 7) The local operator station accesses the authorization management unit of the corresponding relay protection device based on the unique identification code. If the authorization function is disabled, the authorization is denied and a denial log is recorded. If the authorization function is enabled, signature verification can be performed. If signature verification fails, the authorization is denied, authorization information and authorization failure log are recorded, and the authorization function is disabled. If signature verification is successful, the authorization device responds to the master station's instruction, records authorization information and authorization success log, and simultaneously disables the authorization function.
[0056] 8) After receiving the authorization command from the local operator station, the relay protection device verifies the setting file according to the model specification;
[0057] 9) The relay protection device settings are modified according to the update items in the setting document;
[0058] 10) The relay protection device successfully executed the master station setting file reply.
[0059] 11) The main station re-initiates the process of viewing the set value to verify whether the set value has been successfully modified.
[0060] During the aforementioned process of viewing and modifying the settings of relay protection devices at the main station, if the relay protection device fails to receive a signature, fails to apply for authorization, or does not meet the conditions for viewing or modifying settings, it will reply to the main station that it has failed to generate a setting file or execute the setting file.
[0061] As an embodiment of the present invention, the remote operating system for setting relay protection devices includes a local operating station, a master station, and several relay protection devices within the substation. Using the IEC61850 communication device identifier (IEDNAME) as the unique ID for all relay protection devices in the substation, the local operating station can import an SCD (Search Engine Control Center) to instantiate a separate authorization management unit for each relay protection device. The local operating station pre-stores the certificate issued by the master station and uses asymmetric encryption SM2 to negotiate the symmetric key, based on which it conducts SM4 symmetric encryption communication with the master station.
[0062] like Figure 2 As shown, the specific steps for the main station to check the setting N of a certain relay protection are as follows:
[0063] 1) The main station combines the current time, operator information, random string and other information to form authorization information, uses SM3 to perform hash calculation of the message digest, and uses the private key corresponding to the certificate to encrypt the message digest to obtain the signature.
[0064] 2) The master station sends the IEDNAME, authorization information and signature of the relay protection device N to the local operator station via an encrypted channel.
[0065] 3) Local operation station enters the authorization management unit of relay protection device N according to IEDNAME, and uses SM3 to perform hash calculation on the authorization information to obtain an information digest, decrypts the signature by using the public key of the certificate to obtain another group of information digest, and then checks consistency of the two groups. If the check is inconsistent, the authorization information and the check failure log are recorded, and the authorization function is maintained in a closed state; if the check is passed, the authorization information of the unit is updated, the authorization function is opened, and the authorization application of relay protection device N is waited.
[0066] 4) The master station sends the signature to relay protection device N and initiates a viewing setting value request.
[0067] 5) Relay protection device N sends the signature to the local operation station through IEC61850 communication, and requests authorization for responding to the viewing setting value command of the master station.
[0068] 6) The local operation station enters the authorization management unit of relay protection device N based on IEDNAME, and if the authorization function is closed, the authorization is denied this time, and the authorization denial log is recorded. If the authorization function has been opened, the signature is decrypted by using the public key of the certificate, and consistency check is performed on the information digest recorded by the authorization management unit. If the check fails, the authorization is denied this time, the authorization information and the authorization failure log are recorded, and the authorization function is closed; if the check is successful, the device responds to the instruction of the master station, records the authorization information and the authorization success log, and closes the authorization function.
[0069] 7) After receiving the authorization command of the local operation station, relay protection device N generates an original setting value file.
[0070] 8) Relay protection device N notifies the master station that the setting value file is successfully generated.
[0071] 9) The master station calls the setting value file through file service, and checks the setting value file according to the model specification.
[0072] As shown in Figure 3 , the specific steps of the master station for modifying the setting value N of a certain relay protection device are as follows:
[0073] 1) The master station modifies the setting value based on the original setting value file of the relay protection setting value N, and forms an updated setting value file.
[0074] 2) The master station issues the updated setting value file to relay protection device N through file service.
[0075] 3) The master station combines the current time, operator information, updated setting value file related information, random string and other information to form authorization information, uses SM3 to perform hash calculation on the information digest, and uses the private key corresponding to the certificate to perform encryption calculation to obtain a signature.
[0076] 4) The master station sends the IEDNAME, authorization information and signature of the relay protection device N to the local operator station via an encrypted channel.
[0077] 5) The local operator station accesses the authorization management unit of relay protection device N based on the IEDNAME, performs a hash calculation on the authorization information using SM3, decrypts the signature using the certificate's public key to obtain another set of message digests, and then verifies the consistency between the two. If the verification is inconsistent, the authorization information and verification failure log are recorded, and the authorization function remains disabled; if the verification passes, the authorization information of this unit is updated, the authorization function is enabled, and the station awaits authorization requests from relay protection device N.
[0078] 6) The master station will send the signature to the relay protection device N and initiate a request to modify the settings.
[0079] 7) The relay protection device N sends its signature to the local operator station via IEC61850 communication, requesting authorization to respond to the master station's command to modify the settings.
[0080] 8) The local operator station accesses the authorization management unit of relay protection device N based on the IEDNAME. If the authorization function is disabled, the authorization is denied, and a denial authorization log is recorded. If the authorization function is enabled, the signature is decrypted using the certificate's public key, and a consistency check is performed with the message digest recorded by the authorization management unit. If the check fails, the authorization is denied, authorization information and an authorization failure log are recorded, and the authorization function is disabled. If the check succeeds, the authorization device responds to the master station's instruction, records authorization information and an authorization success log, and simultaneously disables the authorization function.
[0081] 9) After receiving the authorization command from the local operator station, the relay protection device N verifies the setting file according to the established rules and setting model specifications.
[0082] 10) The relay protection device N modifies the device settings according to the update items in the setting document.
[0083] 11) The relay protection device N successfully executed the master station setting file.
[0084] 12) The main station re-initiates the process of viewing the set values, and verifies the effectiveness of the set value modification by re-uploading the set value file.
[0085] The above embodiments are merely illustrative of the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made to the technical solutions based on the technical concept proposed in this invention shall fall within the scope of protection of this invention.
Claims
1. A method for remote operation of relay protection device settings, characterized in that... Includes the following steps: Step A: The master station sends the unique identification code, authorization information and signature of the relay protection device to the local operation station via encrypted communication. Step B: The local operating station enters the authorization management unit of the corresponding relay protection device based on the unique identification code, and verifies the validity of the authorization information and signature information. If the verification is successful, the authorization function is enabled. Step C: The master station sends a command to the relay protection device to view or modify the settings, and simultaneously sends the signature. Step D: The relay protection device sends the received signature along with its unique identification code to the local operating station to request authorization; Step E: The local operating station enters the authorization management unit of the corresponding relay protection device based on the unique identification code and performs signature verification. If the signature verification is successful, an authorization command is sent back to the relay protection device; otherwise, authorization is not granted. Step F: The relay protection device, in accordance with the authorized command, responds to the master station's instruction to view or modify settings, and generates or executes a setting file.
2. The method for remote operation of relay protection device settings as described in claim 1, characterized in that: The signature issued by the main station is formed based on the authorization information.
3. The method for remote operation of relay protection device settings as described in claim 1, characterized in that: The local operator station authorization management system instantiates a separate authorization management unit for each relay protection device within the substation.
4. The method for remote operation of relay protection device settings as described in claim 1, characterized in that: The local workstation records authorization log information, including authorization information for each verification.
5. The method for remote operation of relay protection device settings as described in claim 1, characterized in that: Each authorization management unit can have at most one valid authorization message. When the latest authorization message is received, the historical authorization message becomes invalid. Each authorization message can be used for authorization verification at most once. After verification, it becomes invalid immediately. After the authorization message becomes invalid, the authorization management unit will no longer respond to the authorization application of the corresponding relay protection device until the authorization message is updated.
6. The method for remote operation of relay protection device settings as described in claim 1, characterized in that: In step F, the relay protection device responds to the master station's command to view the setting value and generates the original setting value file for the master station to view; or, the relay protection device responds to the master station's command to modify the setting value, parses and verifies the updated setting value file from the master station, and modifies the device setting value.
7. The method for remote operation of relay protection device settings as described in claim 1, characterized in that: Before initiating a command to view or modify settings, the master station regenerates authorization information and sends it to the local operator station to activate the authorization management unit.
8. A remote operating system for setting parameters of a relay protection device, used to implement the remote operation method for setting parameters of a relay protection device as described in any one of claims 1 to 7; characterized in that: Includes a main station, a local operating station, and several relay protection devices; The master station is configured to send the unique identification code, authorization information and signature of the relay protection device to the local operation station via encrypted communication. The local operating station is configured to access the authorization management unit of the corresponding relay protection device based on the unique identification code, and to open the authorization function if the authorization information and signature verification information pass the verification. The master station is also configured to send a command to the relay protection device to view or modify the settings after the authorization function is enabled, and at the same time send the signature; The relay protection device is also configured to send the received signature along with its own unique identification code to the local operating station to request authorization; The local operating station is also configured to enter the authorization management unit of the corresponding relay protection device based on a unique identification code, and perform signature verification. If the signature verification is successful, an authorization command is sent back to the relay protection device; otherwise, authorization is not granted. The relay protection device is also configured to respond to the master station's command to view or modify settings, and to generate or execute settings files according to authorized commands.
Citation Information
Patent Citations
Constant value remote operation method based on transformer substation relay protection device
CN106410964A
Relay device protection setting value checking and correcting method and device, electronic equipment and medium
CN116454825A